Image Privacy Checker
Discover what hidden personal information your photo reveals before you share it. Privately audit location tags, device serial numbers, creator identities, and generative prompts directly in your browser.
Drop your image here
or choose a file from your device
The 4 Hidden Privacy Risks Stored in Photos
When photos are snapped on smartphones, digital cameras, or generated via AI applications, they record rich technical metadata into the file container. If shared uncleaned, these fields expose:
Latitude, longitude, and elevation recorded by phone sensors. Pinpoints private locations such as homes, schools, or workplaces within meters.
Unique camera body and lens serial numbers stored in EXIF MakerNotes. Enables third parties to link unrelated photos across the web back to your specific device.
Photographer credit, copyright lines, and artist names written into IPTC and XMP Dublin Core tags. Deanonymizes anonymous uploads or whistleblowers.
Text prompts stored in AI-generated PNG and JPEG files that inadvertently contain email addresses, personal names, internal project codes, or local file system paths.
How to Audit and Clean Photo Privacy in 4 Steps
- Select your photo: Drop any JPG, PNG, or WebP image into the audit dropzone above.
- Review privacy risks: Examine the threat-level summary (High, Medium, Low) and detected fields.
- Strip sensitive tags: Click "Remove Location & Privacy Tags" to purge GPS, serials, and author headers.
- Independent verification: Review the automated second-pass rescan report confirming all targeted privacy markers are removed, then download.
Technical Scope & Boundaries
Metadata cleaning removes file container headers. It does not alter visual pixel content (such as street signs, house numbers, or reflections visible in the image itself). Always review visual image contents before sharing sensitive photographs publicly.
How We Verify: Lossless Binary Slicing & Independent Two-Pass Verification
We do not ask you to trust that metadata was removed. Every cleaning operation preserves pixel streams without re-encoding and independently validates the output binary before download.
100% Client-Side Processing
All byte manipulation executes locally in browser memory via typed arrays (Uint8Array). Zero image bytes, filenames, or metadata values are transmitted to remote servers.
Bit-for-Bit Pixel Preservation
Rather than re-encoding via canvas, the engine splices container markers directly. JPEG entropy scan data (SOS) and PNG raster chunks (IDAT) remain bit-for-bit identical with zero generational loss.
Two-Pass Rescan Verification
After cleaning, the output binary is re-parsed through the full scanning pipeline. The tool verifies each targeted metadata field independently to prove it is absent from the exported container.
Empirical Test Lab Fixtures
Our parsing and cleaning behavior is tested against synthetic and real-world fixtures spanning GPS IFDs, camera serials, ComfyUI/SD parameters, and 10 C2PA signature scenarios.
Scope & Technical Boundaries: What Metadata Removal Can and Cannot Do
What this tool removes: Embedded container headers and text metadata chunks (EXIF, IPTC, Adobe XMP, PNG ancillary text chunks, ComfyUI workflow graphs, Stable Diffusion prompt parameters, and C2PA JUMBF provenance manifests).
What this tool does not do: It does not alter visual pixel content, remove rasterized visual stamps/watermarks burned into the image pixels, or strip frequency-domain steganographic watermarks (such as Google SynthID or Adobe Digimarc). Furthermore, third-party social media and messaging platforms frequently re-encode uploads, stripping existing metadata or embedding their own platform headers.